Archive for the ‘News’ Category

Mozilla Store got hacked? Don’t let it happen to you.

Wednesday, August 5th, 2009

Unfortunately I have been extremely busy and have been neglecting some of my things which I wanted to do on this here site, primarily my authentication system. Not too long ago I wrote a post on password security and storage.  I have become very security conscious in the past couple years, staying on top of ways to secure data stored in databases, primarily securing passwords and other sensitive material. I voiced my opinion that sites should NEVER store passwords in an unencrypted fashion (plain text) or even a form of encryption that is easily undone. I know this can be a pain in the butt, but unfortunately it’s a necessity now days to secure your client’s data. Today I received an email from the Mozilla Store, warning me that their site had been hacked. Allow me to share this email with you. (I have highlighted the scariest part in red)

August 05, 2009

Dear Valued Mozilla Customer:

It has been brought to our attention that the Mozilla Store www.store.mozilla.org has had a security breach. We take all security breaches very seriously, and are working hard to determine the extent of the violation. In the meantime, the site has been taken down as a protective measure.

At this time we do not believe any credit card information has been compromised. However, some Mozilla Store customers’ user names and passwords have been exposed. It is our strong recommendation that all Mozilla Store customers proactively change their user name and passwords for their Mozilla Store account and all other accounts that use the same information. We will not bring the site back up until we are confident that we have addressed all security issues. A notification will be sent to you when the site goes back up.

GatewayCDI apologizes for any inconvenience this may cause. We value our customers and their online security is a top priority to our organization.

Sincerely,

Conrad Franey
Chief Marketing Officer
GatewayCDI

There are 3 major things I’d like to discuss about this. The first is the obvious, if they had used safe storage techniques; the probability of their password list being compromised would have been practically eliminated. I cannot stress that enough, if a password is in the database as plain text, it will be compromised, I know that means you can’t just send a user their password when they forget, but that’s ok… it’s not a huge hassle to change a password. The second topic is users that “use the same information”. Granted, most of us are guilty of this at some point or another. We all have favorite passwords that we like to use. I personally try to make classifications of passwords for different types of sites, but sometimes I find myself using a “default” password out of habit. Please, people, one of the best ways you can protect yourself on the internet is to use different passwords. If not for everything, don’t use the same password for sites like facebook, myspace, or twitter that you would use for your bank or email account. The third MAJOR topic that I feel needs to be discussed is in regard to that first sentence that’s highlighted in red. “At this time we do not believe any credit card information has been compromised.” This should not even be a fear. Under no circumstances should you store your credit card on any sites database, and under no circumstance should any site store it without your asking. After a transaction is completed, the only thing that should remain is the authorization number, order number, and the last 4 digits of the card. That is all the bank and the company should EVER need to look up a transaction. Verifying identity using a credit card number is a terrible thing, and any company that does so should be avoided. I am hoping that the reason they do not believe any credit card #s were stolen is because they don’t store them… but only time will tell.

Ok, enough ranting and raving from me. I have spoken my mind on this topic, now I will shut up and let you all get back to your days. Just remember, sites do not always practice safe storage procedures, so the best protection from identity theft is still your common sense, so use it!

Our New Blog: We Are ClickPopMedia

Monday, April 28th, 2008

Title

We just launched a new “just for fun” blog.  Don’t worry, we’ll still be posting our regular tutorials and free stuff here, but we just needed this.

So why doncha stop by and see what we like other than pixel patterns, actionscript, and sql queries.  Leave us a comment when you come by.  Or else…

Box2DFlash v2.0.0 Released!

Monday, April 21st, 2008

Box2DFlash v2.0.0 was finally released on the 17th of this month (April). Box2DFlash is the Flash AS3 port of Erin Catto’s C++ physics engine Box2D. Erin Catto is a physics programmer at Blizzard Entertainment (WarCraaaft!). I’ve been looking forward to this release since I found out about it while making a tutorial for the previous release (v1.4.3) about a month ago.
(more…)

The graffiti Gospel…It REALLY is good news.

Wednesday, March 5th, 2008

This week, instead of doing some sort of graffiti tip, demonstration, or overview; I wanted to let you see the beauty of the art being “drawn out.” That way, you can see what writing graffiti is like. I didn’t have time do a piece, tape it and get VQ to edit it because we’re flying to England tonight. So, I started looking for some good footage online.

Gospel Graffiti - Billy Graham Video

In the beginning of my search to find just the right video, I had no idea that a one of this caliber was out there. In it, you’ll see the technicality of graffiti, all the while getting the Truth (his name is Jesus…). Check it out, and pay special attention to how the writers paint over and re-use sections that were previously painted. It’s solid. And props to the GG Crew for their impressive and blessed work.


Be sure to check out the full blog: Gospel Graffiti – Billy Graham Video

“The Lord bless you and keep you…” -Numbers 6:24

-Weese

ClickPopVectors on Vecteezy

Monday, March 3rd, 2008

ClickPopVecteezy

Attention: Our Relief vector pack is up on a really awesome vector image site called Vecteezy. We’re pretty happy to be in the company of the other designers that are featured there. Head on over and vote for us if you appreciate what we do.

GodBless:VQ

The ClickPopLineup (& a vector megaphone)

Tuesday, February 26th, 2008

Today we launch our new blog lineup. In honor of this august occasion, we’re also releasing a little megaphone vector. We’ve been giving you these free resources for quite some time, and now we’re asking for something in return (with great power comes great responsibility you know). We’re asking you to do a composition using the ClickPop vectors themed around “ClickPopHello.” Sorry, there’s no prize for this one other than the warm, fuzzy feeling you will get knowing that you made us smile. Head on over to the ClickPopMedia Flickr group and join in.

Shout Header

Download the Shout! vector pack (Adobe Illustrator)

Back to our new lineup:

  • Paul is going to take Mondays and be blogging about actionscript, things, and stuff.
  • Sean will write on Tuesdays about programming, robots, and DIY.
  • Weese has Wednesdays, and he’ll be writing about graffiti, painting, and the like.
  • VQ is on Thursdays. He’s writing about illustration, and giving out vectors, brushes, and things. Just like Santa Claus.
  • Friday we have a special treat. Ricky Spaniel will be doing a video blog especially for us.
  • We have some cool stuff planned for Saturday and Sunday, but you’ll have to wait a little for that. Remember, patience is a virtue.

Update:

One of our friends from DeviantArt sent us a pretty funny comment:

“Of course, you will know when I use one of your vectors ;) By the way, I’ve watched your video and I laughed a lot when the guy goes crazy :lol:

GodBless:ClickPopMedia